Security News

Microsoft Application Inspector: Check open source components for unwanted features
2020-01-17 12:59

Want to know what's in an open source software component before you use it? Microsoft Application Inspector will tell you what it does and spots potentially unwanted features - or backdoors. "At Microsoft, our software engineers use open source software to provide our customers high-quality software and services. Recognizing the inherent risks in trusting open source software, we created a source code analyzer called Microsoft Application Inspector to identify 'interesting' features and metadata, like the use of cryptography, connecting to a remote entity, and the platforms it runs on," Guy Acosta and Michael Scovetta, security program managers at Customer Security and Trust, Microsoft, explained the Inspector's genesis.

Tricentis acquires SpecFlow to extend support for the open source community
2020-01-17 01:00

SpecFlow will continue to remain a free, open source offering for the software development and testing communities. The acquisition of SpecFlow adds best-in-class support for BDD and.

Fugue open sources Regula to evaluate Terraform for security misconfigurations and compliance violations
2020-01-16 12:58

Fugue has open sourced Regula, a tool that evaluates Terraform infrastructure-as-code for security misconfigurations and compliance violations prior to deployment. Regula rules are written in Rego, the open source policy language employed by the Open Policy Agent project and can be integrated into CI/CD pipelines to prevent cloud infrastructure deployments that may violate security and compliance best practices.

Managing Open Source Components
2019-12-26 18:18

BNP Paribas' Patrick Pitchappa on Application SecurityBecause open source components have known vulnerabilities, it's important for companies to invest in the right tools to help developers build...

Google Promises Upfront Financial Help for Securing Open Source Projects
2019-12-20 09:33

Six years into running the Patch Rewards Program to help improve the security of open source projects, Google has decided to provide upfront financial support for such initiatives. read more

Google Offers Financial Support to Open Source Projects for Cybersecurity
2019-12-18 10:40

Besides rewarding ethical hackers from its pocket for responsibly reporting vulnerabilities in third-party open-source projects, Google today announced financial support for open source developers...

Dynatrace’s open source control plane simplifies IT’s journey to NoOps for cloud native environments
2019-12-13 03:15

Dynatrace announced Keptn, an open source pluggable control plane to advance the industry movement toward autonomous clouds. Keptn provides the automation and orchestration of the processes and...

Your open source gift giving guide for 2019
2019-12-10 22:02

'Tis the season for open source gifts. But what to buy? Jack Wallen has a few ideas that are sure to put a smile on the faces of the open source lovers in your life.

Google Releases Open Source Tool for Finding File Access Vulnerabilities
2019-12-09 15:35

Google on Monday announced that it has released the source code of a tool designed to help developers identify vulnerabilities related to file access. read more

Cisco Talos Releases Open Source Dependency Build Automation Tool
2019-12-05 14:35

Cisco Talos this week released a new tool designed to make it easier to create complex applications that have lengthy dependency chains. Called Mussels, the cross-platform, general-purpose...